The New Logon fields indicate the account for whom the new logon was created, i.e. https://social.technet.microsoft.com/Forums/office/en-US/fa4e025c-8d6b-40c2-a834-bcf9f96ccbb5/nps-fails-with-no-domain-controller-available. In step 4 to configure network policy, also check the box to Ignore user account dial-in properties. Below is the link of NPS server extensions logs uploaded on onedrive, https://1drv.ms/u/s!AhzuhBkXC04SbDWjejAPfqNYl-k?e=jxYOsy, Hi Marilee, i fixed the issue after reviewing the logs in detail all good now and working as expected. RDSGateway.mydomain.org The authentication method used was: NTLM and connection protocol used: HTTP. When I try to connect I received that error message Event Log Windows->TermainServices-Gateway. did not meet connection authorization policy requirements and was Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support. Please click "Accept Answer" and upvote it if the answer is helpful. We even tried to restore VM from backup and still the same. The authentication method used was: "NTLM" and connection protocol used: "HTTP". What roles have been installed in your RDS deployment? In our case the problem is that the Pre-Windows 2000 name (NETBIOS) is also a possible DNS suffix which create issue. The user "~redacted", on client computer "redacted", did not meet connection authorization policy requirements and was therefore not authorized to access the RD Gateway server. Ours only affects certain users, and I cannot find a pattern or anything special about these accounts. The following error occurred: "23003". I'm using windows server 2012 r2. Welcome to the Snap! Network Policy Name:- Where do I provide policy to allow users to connect to their workstations (via the gateway)? The Wizard adds it to the install process or it's supposed to but I've seen the Wizard do weirder things. I've been doing help desk for 10 years or so. NPS is running on a separate server with the Azure MFA NPS extension installed. No: The information was not helpful / Partially helpful. Event ID: 201 The user successfully logs into RDS Web utility but fails to open an app on one collection, but the attempt succeeds on another collection. Google only comes up with hits on this error that seem to be machine level/global issues. Event ID 200, Source TerminalServices-Gateway: This event indicates that the client connected to the TS Gateway server. I even removed everything and inserted Domain Users, which still failed. Not applicable (no computer group is specified) Cookie Notice Absolutely no domain controller issues. The authentication method used was: "NTLM" and connection protocol used: "HTTP". Copyright 2021 Netsurion. Yup; all good. https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-register) should fix that issue, I register the server. For the most part this works great. By rejecting non-essential cookies, Reddit may still use certain cookies to ensure the proper functionality of our platform. I again received: A logon was attempted using explicit credentials. A reddit dedicated to the profession of Computer System Administration. But I am not really sure what was changed. The user "XXXXXX", on client computer "XX.XX.XX.XX", did not meet connection authorization policy requirements and was therefore not authorized to access the RD Gateway server. XXX.XXX.XXX.XXX Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Recently I setup RDS server in Windows Server 2016. all components seems working well (RD Connection Broker, RD Session Host, RD Gateway, RD Licensing, RD Web Access). The following error occurred: "23003". 0 Authentication Provider:Windows Once I made this change, I was able to successfully connect to a server using the new remote desktop gateway service. Remote Desktop Sign in to follow 0 comments The user "RAOGB\user2", on client computer "144.138.38.235", did not meet connection authorization policy requirements and was therefore not authorized to access the RD Gateway server. during this logon session. POLICY",1,,,. Hello! In the main section, click the "Change Log File Properties". A Microsoft app that connects remotely to computers and to virtual apps and desktops. New comments cannot be posted and votes cannot be cast. The authentication method used was: "NTLM" and connection protocol used: "HTTP". Based on my research and lab tests, I found that we do not need to configure from the NPS side but only need to set RAP and CAP from RD gateway side. For more information, please see our Many thanks to TechNet forum user Herman Bonnie for posting the very helpful comment. access. The authentication method used was: NTLM and connection protocol used: HTTP. We are seeing this generic error on Windows when trying to connect: Remote Desktop can't connect to the remote computer.for one of these reasons: 1) Your user account is not authorized to access the RD Gateway 2) Your computer is not authorized to access the RG Gateway 3) You are using an incompatible authentication method The authentication method used was: "NTLM" and connection protocol used: "HTTP". Thanks. This site uses Akismet to reduce spam. The following error occurred: "23003". The authentication method used was: "NTLM" and connection protocol used: "HTTP". At this point I didnt care for why it couldnt log, I just wanted to use the gateway. access. authentication method used was: "NTLM" and connection protocol used: "HTTP". 56407 The following error occurred: "%5". The authentication method used was: "NTLM" and connection protocol used: "HTTP". The following error occurred: "23003". The following error occurred: 23003. The following error occurred: "23003". Hi, I If the client settings and TS CAP settings are not compatible, do one of the following: Modify the settings of the existing TS CAP. Sr. System Administrator at the University of Vermont, the official documentation from Microsoft, Preventing Petya ransomware with Group Policy. ** 02/18/2019 21:02:56 6",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"TS GATEWAY AUTHORIZATION Remote Desktop Gateway Service - register NPS - Geoff @ UVM In the security Audit event log I foundthe following 4 event: The user get authenticated, but for a unknown reason, the policy block it. Anyone have any ideas? POLICY",1,,,. thanks for your understanding. I double-checked the groups I had added to the CAP and verified the account I was using should be authorized. ** 02/18/2019 21:02:56 6",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"TS GATEWAY AUTHORIZATION POLICY",1,,,, This topic has been locked by an administrator and is no longer open for commenting. User: NETWORK SERVICE I had checked my Remote Desktop Users is added group domain\domain users, and also RD CAP and RD RAP. Microsoft does not guarantee the accuracy of this information. Since we had not made any recent changes or updates, a simple reboot of the firewall and it's failover device resolved the problem. We work side-by-side with you to rapidly detect cyberthreats and thwart attacks before they cause damage. The following error occurred: "23003". And I still need to bypass the NPS authentification have the RD Gateway fonctionnal. Please share any logs that you have. The authentication method used was: "NTLM" and connection protocol used: "HTTP". What is your target server that the client machine will connect via the RD gateway? Source: Microsoft-Windows-TerminalServices-Gateway Level: Error The following authentication method was used: "NTLM". The following error occurred: "23002". The log file countain data, I cross reference the datetime of the event log In the TS Gateway Manager console tree, select the node that represents the local TS Gateway server, which is named for the computer on which the TS Gateway server is running. The error is The user "DOMAIN\USER", on client computer "172.31.48.1", did not meet connection authorization policy requirements and was therefore not authorized to access the RD Gateway server.